diff --git a/internal/middleware/csrf_test.go b/internal/middleware/csrf_test.go index a515dd2..1b58fec 100644 --- a/internal/middleware/csrf_test.go +++ b/internal/middleware/csrf_test.go @@ -94,6 +94,23 @@ func TestCSRFTokenValidationMissingCookie(t *testing.T) { } } +func TestCSRFTokenValidationOnlyCookie(t *testing.T) { + token, err := CSRFToken() + if err != nil { + t.Fatalf("Failed to generate CSRF token: %v", err) + } + + request := httptest.NewRequest("POST", "/test", nil) + request.AddCookie(&http.Cookie{ + Name: CSRFTokenCookieName, + Value: token, + }) + + if ValidateCSRFToken(request) { + t.Error("Request with only cookie (no form/header token) should fail validation") + } +} + func TestCSRFTokenValidationHeader(t *testing.T) { token, err := CSRFToken() if err != nil {